Executive Summary
In 2026, security researchers at Forever Security demonstrated that malicious browser extensions could hijack AI assistants across five major Chromium-based browsers including Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The attack, dubbed BragJack, exploited common extension permissions to seize control of trusted web pages that communicate with AI agents, allowing attackers to read local files, access cameras and microphones, and control AI functionality. The vulnerabilities were assigned CVE-2026-0628 (Chrome) and CVE-2026-55945 (Edge), with researchers earning approximately $20,000 in bug bounties across the affected platforms.
This incident highlights the emerging security risks of browser-integrated AI agents as vendors race to embed autonomous AI capabilities directly into web browsers. The attack vectors demonstrate how traditional browser security boundaries are being challenged by AI integration, creating new pathways for privilege escalation and data exfiltration that require updated security models.
Why This Matters Now
Browser-integrated AI agents are rapidly becoming mainstream, with major vendors embedding autonomous AI capabilities that can access sensitive user data and system resources. This creates new attack surfaces where traditional browser security models may be insufficient to protect against AI-specific exploitation techniques.
Attack Path Analysis
Attacker deploys malicious browser extension with common permissions (web page modification and declarativeNetRequest) to hijack AI assistants across multiple Chromium-based browsers. Extension intercepts trusted communication channels between AI agents and their control servers, enabling unauthorized command execution, file access, camera/microphone activation, and potential data exfiltration through compromised AI capabilities.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Malicious browser extension installed with deceptive permissions (web page modification and declarativeNetRequest) that appear legitimate to users, similar to ad blockers
Related CVEs
CVE-2026-0628
CVSS 8.8Browser extension vulnerability allowing malicious extensions to hijack AI assistants through declarativeNetRequest and content script permissions in Chromium-based browsers.
Affected Products:
Google Chrome – < 143.0.7499.192
Exploit Status:
proof of conceptCVE-2026-55945
CVSS 4.2Microsoft Edge vulnerability allowing malicious browser extensions to control AI assistant functionality through compromised web pages.
Affected Products:
Microsoft Edge – < 150.0.4078.48
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Phishing
Process Injection
Browser Extensions
Data from Information Repositories
Audio Capture
Video Capture
Screen Capture
Data from Local System
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing
Control ID: 500.15
DORA – ICT Third-Party Risk Management
Control ID: Article 8
CISA ZTMM 2.0 – Application Layer Security Controls
Control ID: Application Security
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Secure Development Policy
Control ID: A.14.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Browser extension vulnerabilities enabling AI assistant hijacking pose critical risks to financial data access, customer privacy, and regulatory compliance under strict industry standards.
Health Care / Life Sciences
AI assistant compromises through browser extensions threaten patient data confidentiality, HIPAA compliance violations, and unauthorized access to sensitive medical information systems.
Computer Software/Engineering
Extension-based AI hijacking attacks directly impact software development environments, code repositories, intellectual property protection, and secure development lifecycle processes.
Government Administration
Browser security vulnerabilities affecting AI assistants create significant risks for classified information access, citizen data protection, and critical government operations security.
Sources
- One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claudehttps://thehackernews.com/2026/09/one-extension-could-hijack-ai.htmlVerified
- BragJack: Hijacking 5 Browsers via Built-in AI Assistantshttps://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistantsVerified
- CVE-2026-0628 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2026-0628Verified
- CVE-2026-55945 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2026-55945Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the attack's reach by constraining network access paths and limiting lateral movement between browser-based AI agents. Zero trust segmentation could have reduced the blast radius across multiple browser platforms and restricted unauthorized data exfiltration channels.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely constrain the extension's ability to establish unauthorized connections to external command infrastructure, reducing its operational scope within the browser environment
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely limit the extension's ability to impersonate legitimate AI service communications, constraining privilege escalation across different browser contexts and AI assistant interfaces
Control: East-West Traffic Security
Mitigation: Microsegmentation policies would likely constrain cross-browser communication pathways, reducing the extension's ability to propagate control mechanisms across multiple AI assistant platforms and browser environments
Control: Multicloud Visibility & Control
Mitigation: Comprehensive traffic analysis would likely identify anomalous communication patterns within AI service channels, constraining the attacker's ability to maintain persistent command infrastructure through compromised agent interfaces
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely restrict unauthorized data transmission pathways, constraining the volume and types of sensitive information that could be exfiltrated through compromised AI service channels
While device-level access may persist, network-based controls would likely constrain the attacker's ability to leverage compromised browser resources for broader network reconnaissance or infrastructure targeting beyond the initial endpoint
Impact at a Glance
Affected Business Functions
- Web Browsing Security
- AI Assistant Services
- Data Privacy Protection
- Enterprise Browser Management
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of local files, camera and microphone access, browser profiles, browsing history, and screenshots depending on the affected browser and AI assistant combination.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Cloud Native Security Fabric (CNSF) with inline enforcement to detect and block malicious extension behaviors targeting AI assistants and autonomous systems
- • Deploy egress security and policy enforcement to monitor and control AI agent communications to external services, preventing unauthorized data exfiltration
- • Establish zero trust segmentation with identity-based policies to limit browser extension privileges and AI agent access to sensitive resources
- • Enable multicloud visibility and control to detect anomalous interactions between browser extensions and AI services across different platforms
- • Implement threat detection and anomaly response capabilities to baseline normal AI assistant behavior and alert on suspicious automation or malformed requests



